CC cheat sheet
148 key facts across 5 exam domains, distilled from the full CC revision notes — with the exam pattern behind each topic. Skim it the week of your exam.
Updated
Security Principles
24% of the examCIA Triad, AAA, and Non-Repudiation: Core ISC2 CC Security Concepts
- CIA = Confidentiality (only authorized eyes), Integrity (accurate and unaltered), Availability (usable when needed)
- Match controls to properties: encryption protects confidentiality, hashing protects integrity, backups and redundancy protect availability
- DoS attacks and ransomware target availability; unauthorized modification targets integrity; snooping and breaches target confidentiality
- The three A's run in order: authentication proves who you are, authorization decides what you may do, accounting records what you did
- MFA requires two or more different factor types (know, have, are) - a password plus a PIN is still single-factor
- Non-repudiation means an action cannot be credibly denied; digital signatures are the primary mechanism
- Privacy governs personal data (PII) end to end - it uses confidentiality controls but also limits collection, use, and retention
How the exam tests this
The CC exam tests this sub-domain almost entirely through definition-matching and short scenarios: an incident is described and you name the CIA property violated, or a login flow is described and you label each step as authentication, authorization, or accounting. Watch trigger words - altered or tampered points to integrity, disclosed or viewed to confidentiality, unavailable or offline to availability, cannot deny to non-repudiation, and personal data or PII to privacy. Expect at least one question checking that MFA requires different factor types, and one mapping a control (encryption, hashing, backups, digital signature) to the property it protects.
Risk Management for the ISC2 CC Exam: Lifecycle, Assessment, and Treatment
- Risk = likelihood x impact; it exists only where a threat can exploit a vulnerability in an asset
- Threat is the external potential for harm; vulnerability is the internal weakness it exploits - keep them separate
- The lifecycle runs identify, assess, treat, monitor - and repeats forever; identification always comes first
- Qualitative assessment uses low/medium/high ratings and judgment; quantitative uses monetary values and expected loss
- The four risk responses are avoid (stop the activity), mitigate (apply controls), transfer (insurance/outsourcing), accept (documented, informed decision)
- Transfer shifts financial impact but never accountability; ignoring a risk is not acceptance
- Residual risk is what remains after controls - the goal is residual risk within the organization's appetite and tolerance, not zero risk
- Management, not the security analyst, formally accepts risk on behalf of the organization
How the exam tests this
The CC exam probes this sub-domain with vocabulary matching and scenario classification: a one-line situation is described and you name the concept or the risk response. Watch the trigger words - insurance or outsourcing signals transfer, discontinuing an activity signals avoidance, patching or adding controls signals mitigation, and a documented sign-off signals acceptance. Expect questions separating threat from vulnerability, qualitative (ratings, matrix) from quantitative (dollar values), and residual from inherent risk, plus at least one asking what remains after controls are applied or who has authority to accept risk (management).
Security Governance: Laws, Frameworks, Policies, Standards, Procedures
- Laws and regulations are mandatory, externally imposed, and enforced with penalties
- GDPR protects EU personal data; HIPAA protects US health information: both are laws, not frameworks
- Frameworks such as the NIST CSF and ISO/IEC 27001 are voluntary structures for building a security program
- A policy is a mandatory, high-level statement of management intent
- A standard sets specific, measurable, mandatory requirements that support a policy
- A procedure is a mandatory step-by-step instruction for performing a task
- A guideline is the only optional document: it recommends, it never requires
- Detail increases as you move down: policy to standard to procedure
How the exam tests this
The CC exam tests this sub-domain almost entirely through classification. Expect a described document and a question asking whether it is a policy, standard, procedure, or guideline: high-level and management intent signal policy, specific required values signal standard, step-by-step signals procedure, and recommended or optional signals guideline. Also expect questions asking which item in a list is voluntary, where a framework such as the NIST CSF or ISO/IEC 27001 is the answer, versus mandatory laws such as GDPR and HIPAA. Remember that the guideline is the only optional internal document.
Security Controls: Technical, Administrative, and Physical Types
- Control type describes implementation: technical (logical), administrative (managerial), or physical
- Technical controls are enforced by hardware and software: firewalls, encryption, ACLs, IDS and IPS, MFA
- Administrative controls work through people and process: policies, training, background checks, risk assessments
- Physical controls protect tangible spaces: locks, guards, fences, badges, CCTV, mantraps
- A written password policy is administrative; the system enforcing it is technical
- Defense in depth layers controls of all three types so no single failure exposes the asset
- Functions describe purpose: preventive stops, detective finds, corrective restores, deterrent discourages, compensating substitutes
- One control has one type but can serve several functions, like CCTV being physical, detective, and deterrent
How the exam tests this
The CC exam tests this sub-domain with rapid classification questions: a control is named or described and you pick its type, its function, or both. Trigger words for type are enforcement mechanism cues: software and automatic filtering signal technical, policy, training, and background check signal administrative, and barriers, guards, badges, and cameras signal physical. Function questions hinge on outcome verbs: stops or blocks means preventive, identifies or records means detective, restores means corrective, discourages means deterrent, and substitutes for an infeasible control means compensating. Watch the classic traps: the badge reader and the guard are physical, the written policy is administrative while the enforcing system is technical, and a visible camera is detective and deterrent at once.
ISC2 Code of Ethics, Due Care, and Due Diligence for the CC Exam
- Due care is action: taking the reasonable precautions a prudent person would take.
- Due diligence is investigation: the ongoing research and verification that informs due care.
- The four ISC2 canons in priority order: protect society; act honorably; serve principals; advance the profession.
- When canons conflict, the higher-listed canon always wins; duty to society outranks duty to an employer.
- Canon two makes legality a floor: unlawful conduct is automatically a Code violation.
- Adherence to the Code is a condition of certification; violations can be investigated and can cost you the credential.
- Prudent person in a question signals due care; assessing or verifying signals due diligence.
- Serving a principal never justifies harming the public or acting dishonestly.
How the exam tests this
The CC exam tests this sub-domain with scenario questions: expect a described situation followed by which concept applies or what should you do. Trigger words to watch: prudent person and reasonable precautions signal due care, while assess, research, investigate, and verify signal due diligence. Canon questions hinge on the required priority order, often by putting duty to an employer against duty to the public and crediting the answer that protects society first through responsible channels. Also expect a direct recall item on the canons' order or on the fact that violating the Code can cost you the certification.
Security Governance
17% of the examGovernance, Risk, and Compliance (GRC) for the ISC2 CC Exam
- Governance is leadership setting direction: policy, accountability, and alignment of security with business objectives.
- Governance decides what should happen and verifies it did; management executes it day to day.
- Risk management keeps the organization operating within the risk appetite set by leadership.
- Compliance covers external laws and regulations plus the organization's own internal policies.
- Audits, internal and external, verify compliance by testing controls and reviewing evidence.
- Integrating GRC into one program prevents silos, duplicated effort, and inconsistent decisions.
- A GRC platform centralizes policies, risk registers, control mappings, and compliance evidence.
How the exam tests this
The CC exam tests GRC at recognition depth: expect definition questions and short scenarios that describe an activity and ask whether it is governance, risk, or compliance. Trigger words are your friend: 'sets direction', 'policy', 'accountability', and 'aligns with business objectives' point to governance; 'likelihood', 'impact', 'appetite', 'register', and 'treatment' point to risk; 'law', 'regulation', 'audit', and 'evidence' point to compliance. Also expect one question separating governance, which decides what should happen, from management, which carries it out, and a purpose question whose answer is that integrating the three pillars avoids silos and produces consistent decisions and audit evidence.
Business Continuity, Disaster Recovery, and Redundancy Explained
- BC keeps critical business functions running during a disruption; DR restores IT systems and data after it.
- DR is a subset of BC: BC covers people, processes, and facilities, while DR focuses only on IT.
- The BIA comes first: it identifies critical functions and their maximum tolerable downtime, and plans are built on it.
- RTO is how quickly a system must be restored: it measures downtime, forward from the outage.
- RPO is how much data loss is tolerable: it measures backward in time and dictates backup frequency.
- RAID and failover are redundancy against component failure; they are not backups and do not undo deletion or ransomware.
- Hot sites recover fastest at the highest cost, cold sites are cheapest but slowest, and warm sites sit between.
- An untested backup or DR plan is unproven: restores and recovery procedures must be exercised.
How the exam tests this
The CC exam probes this topic with precise definition swaps. If a scenario says how quickly a system must be restored or mentions maximum downtime, that is RTO; if it says how much data can be lost or asks how old the last backup may be, that is RPO, and RPO maps to backup frequency. 'Keep the business operating during a disruption' signals business continuity, while 'restore IT systems and data after the event' signals disaster recovery, with DR always a subset of BC. Expect recognition questions matching hot, warm, and cold sites to their cost and recovery speed, remembering that the BIA identifies critical functions and tolerable downtime before any plan is written, and knowing that RAID is redundancy, not a backup.
Security Awareness: Social Engineering, Phishing, and Password Hygiene
- Security is everyone's responsibility; leadership tone from the top and a blame-free reporting culture make awareness effective
- Social engineering manipulates people using authority, urgency, scarcity, familiarity, intimidation, and social proof
- Phishing is email-based; spear phishing targets a specific person, and whaling targets executives
- Smishing is phishing over SMS text messages; vishing is phishing over voice calls
- Pretexting invents a false scenario, baiting lures victims with a tempting item, and tailgating follows someone through a secure door
- Prefer long unique passphrases over short complex passwords, never reuse passwords, and use a password manager
- Multi-factor authentication defeats most credential theft because a stolen password alone is not enough
- The correct user response to a suspected attack is do not interact, verify out of band, and report it immediately
How the exam tests this
The CC exam tests sub-domain 2.3 with definition-matching questions: expect a short scenario and four attack names, where the channel and target are the clues. Trigger words include voice call for vishing, text message for smishing, executive or CEO for whaling, personalized email for spear phishing, fabricated scenario for pretexting, USB drive for baiting, and follows through the door for tailgating. Culture questions reward tone from the top and blame-free reporting, and password questions reward length, uniqueness, password managers, and MFA over complexity rules.
Measuring Security Effectiveness: Metrics, KPIs, and Key Risk Indicators
- You cannot manage what you do not measure; metrics turn security from faith into evidence for decisions
- Good metrics are meaningful and actionable; a number nobody acts on is a vanity metric
- Core security KPIs include patching timeliness, incident counts, MTTD, MTTR, and training completion rates
- MTTD measures time to discover an incident; MTTR measures time from detection to containment; shorter is better for both
- A KRI is a forward-looking, leading indicator that warns risk is rising before an incident occurs
- A KPI is typically a lagging measure of past performance; KRI wording cues are early warning and leading indicator
- KRIs are paired with thresholds that trigger escalation to management when crossed
- Dashboards give real-time operational views, scorecards rate performance against targets, and reports add narrative and recommendations tailored to the audience
How the exam tests this
The CC exam probes sub-domain 2.4 mainly through the KPI versus KRI distinction: watch for trigger phrases like leading indicator, early warning, and signals rising risk, which mean KRI, versus measures performance or tracks achievement of goals, which mean KPI. Expect definition questions on MTTD versus MTTR, where the boundary is the moment of detection, and on which common metric fits a described purpose, such as training completion for the human layer. Communication questions test matching the vehicle and detail level to the audience: dashboards for real-time operations, scorecards for targets, narrative reports and risk-framed summaries for executives and the board.
Identity And Access Management (IAM) Concepts
20% of the examIdentity Life Cycle Management: Provisioning, Review, and Deprovisioning
- The identity life cycle is roles definition, provisioning, review, and deprovisioning, mapped to Joiner-Mover-Leaver.
- Define the access a role needs before granting it, and provision only that access: least privilege starts at provisioning.
- Every user gets a unique account; shared accounts destroy accountability.
- Privilege creep is the mover risk; periodic access reviews (recertification or attestation) detect and revoke unneeded access.
- Deprovision promptly at separation: disable first to preserve audit data, delete later per retention policy.
- An active account whose owner has left is an orphaned account, a prime attacker target.
- For involuntary terminations, disable access at or before the moment the person is told.
- IAM and IGA tools automate provisioning and deprovisioning, removing the delays that create orphaned accounts.
How the exam tests this
The CC exam tests this sub-domain with short scenarios keyed to Joiner-Mover-Leaver events. Trigger words include new hire (provisioning), transferred or changed roles (access review and privilege creep), and terminated or resigned (immediate deprovisioning). Expect at least one question where a departed employee still has an active account: the answer names the orphaned account risk or the missing deprovisioning step. Questions using recertification or attestation are asking about periodic access reviews.
Logical Access Controls: Least Privilege, DAC, MAC, and RBAC
- Least privilege: grant the minimum access the job requires; need-to-know further restricts specific information.
- Separation of Duties splits a sensitive process so no one person can commit and conceal fraud; collusion becomes required.
- Dual control means two people act together on one task; job rotation and mandatory vacations detect long-running fraud.
- DAC: the resource owner decides; flexible, common in operating systems, weakest central control.
- MAC: the system enforces labels against clearances; most rigid, used in military and high-security settings; users cannot override.
- RBAC: access follows the job role; the scalable enterprise model and a defense against privilege creep.
- ABAC grants access by evaluating attributes and conditions such as department, device, and time.
- When a question asks which model, ask who decides: owner (DAC), system (MAC), role (RBAC), attributes (ABAC).
How the exam tests this
The CC exam gives one-line scenarios and asks which model or principle applies. Owner decides or a user shares a file points to DAC; labels, classifications, and clearances point to MAC; access by job function points to RBAC; attributes and conditions point to ABAC. Least privilege questions hinge on the word minimum, and Separation of Duties questions describe one person controlling an entire sensitive process, with the fix being to split it between people.
Networking and Cloud Security Concepts
22% of the examNetwork Security Basics: OSI Model, TCP/IP, Firewalls, and VPNs
- The OSI model has seven layers; the TCP/IP model has four, with the TCP/IP Application layer covering OSI layers 5 to 7.
- IP addresses and routing are Layer 3; MAC addresses and switches are Layer 2; TCP and UDP with port numbers are Layer 4.
- IPv4 addresses are 32-bit; IPv6 addresses are 128-bit, created because IPv4 addresses ran out.
- Firewalls filter traffic by rules on addresses, ports, and applications; stateful firewalls track connections while stateless ones judge each packet alone.
- Know the core ports: 22 SSH, 53 DNS, 80 HTTP, 443 HTTPS; Telnet on 23 and HTTP on 80 are the insecure versions of SSH and HTTPS.
- A VPN is an encrypted tunnel over an untrusted network that provides confidentiality; remote access connects one user, site-to-site connects whole networks.
- Use WPA3 or WPA2 for Wi-Fi; WEP and open networks are insecure, and Bluetooth should be non-discoverable when not pairing.
- IoT, embedded, and ICS devices are long-lived, rarely patched, and ship with weak defaults, so isolate them on their own network segment.
How the exam tests this
The CC exam tests this sub-domain at recognition depth: expect definition-match questions such as which OSI layer handles routing (Network, Layer 3), how many layers each model has (OSI seven, TCP/IP four), and which address is 128-bit (IPv6). Port questions give you a service and ask the number or the reverse, favoring the secure-insecure pairs 22/23 and 443/80. Scenario stems about working on public Wi-Fi point at VPNs and confidentiality, while stems about devices that cannot be patched, such as cameras or plant controllers, point at IoT and ICS with segmentation as the control. Trigger words include encrypted tunnel (VPN), tracks connection state (stateful firewall), and never patched with default passwords (IoT).
Network Security Architecture: Zero Trust, Defense in Depth, Segmentation
- Segmentation limits lateral movement: an attacker's foothold in one zone cannot freely reach systems in another.
- The DMZ is a buffer zone between the untrusted internet and the trusted internal network, and it is where public-facing servers belong.
- VLANs segment a network logically at Layer 2, letting one physical switch act as several isolated networks whose interconnections cross a control point.
- Micro-segmentation applies policy per individual workload, stopping lateral movement even between servers in the same segment.
- Defense in Depth layers multiple independent controls so that no single control's failure exposes the asset.
- Zero Trust's core principle is never trust, always verify: no implicit trust based on network location, every request authenticated and authorized.
- Zero Trust enforces least privilege, assumes breach, and uses micro-segmentation as a key enabler; it is an architecture, not a product.
- The castle-and-moat model fails because implicit trust by location cannot stop insiders, stolen credentials, or lateral movement.
How the exam tests this
Expect definition-match and scenario questions. The highest-yield item is Zero Trust's core principle, which you must recognize verbatim: never trust, always verify, with no implicit trust based on network location; distractors will offer trust but verify or trust internal users only. DMZ questions describe hosting a public-facing server or a segment between the internet and the internal network. Trigger words include lateral movement and blast radius (segmentation), logical Layer 2 separation (VLAN), per-workload policy (micro-segmentation), layered controls with no single point of failure (Defense in Depth), and assume breach or least privilege (Zero Trust).
Cloud Security: Shared Responsibility, IaaS vs PaaS vs SaaS, Deployment Models
- The five essential cloud characteristics: on-demand self-service, broad network access, resource pooling, rapid elasticity, measured service.
- IaaS rents infrastructure (you manage the OS up), PaaS rents a managed platform (you bring code and data), SaaS rents a finished application (you bring data and users).
- Deployment models by tenant: public (everyone), private (one organization), community (a group with shared requirements), hybrid (a bound combination).
- Shared responsibility: the provider secures the cloud (physical, hardware, virtualization); the customer secures what is in the cloud (data, access, configuration).
- Customer responsibility is greatest in IaaS, smaller in PaaS, and smallest in SaaS - the more the provider manages, the more security it absorbs.
- The customer is always responsible for their data, identities, and configuration, in every service model - including SaaS.
- In IaaS the customer patches the operating system; in PaaS and SaaS the provider does.
- A publicly exposed storage bucket is a customer misconfiguration, not a provider failure - accountability for data never transfers to the provider.
How the exam tests this
The CC exam tests cloud security at recognition depth: matching one-sentence definitions to the five NIST characteristics, the three service models, and the four deployment models, and assigning responsibility for a given stack layer under the shared responsibility model. Trigger words include self-service and pay-per-use (characteristics), who manages the OS (service model boundaries), single organization versus shared group (deployment models), and misconfigured or publicly exposed storage (customer-side failure). Expect at least one question confirming that the customer always owns data and identities in every model, including SaaS, and one asking who patches the operating system in IaaS versus PaaS.
Security Operations and Incident Response
17% of the examData Security: Classification, Masking, Sanitization, and Encryption Basics
- Classification labels data by sensitivity (for example public, internal, confidential, restricted), and the label determines how strongly the data is protected.
- Masking obscures displayed values (showing only the last four digits); the underlying data still exists and there is no key to reverse it.
- Deleting or quick-formatting is not sanitization - the data remains recoverable; true sanitization is overwriting, degaussing (magnetic media only), or physical destruction.
- Data has three states - at rest (stored), in transit (moving), in use (processed) - and each needs protection.
- Symmetric encryption uses one shared key, is fast, suits bulk data (AES); its weakness is key distribution.
- Asymmetric encryption uses a public and private key pair (RSA), solves key distribution, enables digital signatures, but is slow.
- Hashing (SHA-256) is one-way, keyless, and proves integrity - it is not encryption and provides no confidentiality.
- Quantum-resistant (post-quantum) cryptography means algorithms designed to withstand attacks from quantum computers, which chiefly threaten today's asymmetric algorithms.
How the exam tests this
The CC exam tests data security by definition matching and look-alike traps: given a description, name the concept - the label that drives protection (classification), showing only the last four digits (masking), making data unrecoverable before disposal (sanitization), one shared key (symmetric), a public and private key pair (asymmetric), one-way with no key (hashing). Expect a trap answer offering deletion or formatting as secure destruction, and another offering hashing as a way to keep data confidential - both are wrong. Trigger words include AES and bulk data for symmetric, RSA, key distribution and digital signatures for asymmetric, SHA-256 and integrity for hashing, degaussing and overwriting for sanitization, and quantum-resistant or post-quantum for the new outline bullet.
Security Operations: Logging, Monitoring, SIEM and Threat Intelligence
- Logs are the record of system events; monitoring means reviewing them continuously, not just after a breach.
- A SIEM aggregates, normalizes, and correlates logs from across the environment and raises alerts; the SOC operates it.
- Triage prioritizes security events by severity and business impact so analysts work the riskiest alerts first.
- Correlation links related events from different systems into one picture and reduces false positives.
- Match actors to motives: nation-state/APT = espionage, organized crime = money, hacktivist = ideology, insider = access abuse, script kiddie = notoriety.
- CTI turns threat data into actionable knowledge at strategic (executives), operational (managers), and tactical (SOC analysts) levels.
- MITRE ATT&CK catalogs adversary tactics (why) and techniques (how); the Cyber Kill Chain is a 7-stage attack sequence, and breaking one link stops the attack.
How the exam tests this
The CC exam tests this sub-domain with definition-matching and scenario questions at recognition depth. Expect to identify the SIEM as the tool that aggregates and correlates logs and generates alerts, and the SOC as the team that monitors them. Scenario stems describe an attacker's behavior or motive and ask you to name the threat actor: well-funded and espionage-driven signals nation-state/APT, ransom demands signal organized crime, cause-driven defacement signals hacktivist. Trigger words include correlation, false positive, prioritization by impact, actionable intelligence, tactics and techniques (ATT&CK), and the ordered stages of the Cyber Kill Chain.
Incident Response: The IR Plan, Phases, CSIRT and Tabletop Exercises
- An event is any observable occurrence; an incident is an event that harms or threatens confidentiality, integrity, or availability.
- The IRP is written and approved before an incident and defines roles, criteria, escalation paths, and procedures.
- NIST phase order: Preparation, then Detection and Analysis, then Containment, Eradication and Recovery, then Post-Incident Activity.
- Within the response: contain first to stop the spread, eradicate the cause, then recover systems, never in reverse order.
- SANS PICERL (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) is the same process in six steps.
- The CSIRT is a predefined cross-functional team: lead, technical analysts, management, legal, communications, and HR.
- Chain of custody is the documented, unbroken record of who handled evidence, when, and how; a broken chain can make evidence inadmissible.
- A tabletop exercise rehearses the plan through a scripted discussion, without touching production, and plans must be tested regularly.
How the exam tests this
The CC exam probes this sub-domain with order and definition questions. Expect to pick the correct NIST phase sequence (Preparation; Detection and Analysis; Containment, Eradication and Recovery; Post-Incident Activity) and to spot broken orders such as recovering before eradicating. Definition stems contrast event with incident, so watch for the harm-to-CIA trigger, and recognize the CSIRT as the predefined cross-functional response team. Scenario questions describe a discussion-based rehearsal of the plan and expect the answer tabletop exercise, or describe documented evidence handling and expect chain of custody.
Asset Lifecycle, Configuration Management, and Change Management
- You cannot protect what you do not know you have: the asset inventory is the foundation of asset protection.
- The asset lifecycle runs acquisition, deployment, use, maintenance, and secure disposal, with security duties at every stage.
- End of life assets receive no more security patches, so they must be replaced or, failing that, isolated and monitored.
- Media must be sanitized (overwritten, degaussed) or physically destroyed before disposal; deleting and reformatting are not enough.
- A secure baseline is the documented, approved, hardened configuration every system of a type must match.
- Configuration drift is unplanned deviation from the baseline; detect it with audits and correct it through change management.
- The change management order is request, review and approval, test, implement, document, with a rollback plan prepared before implementing.
- Emergency changes may be implemented before full approval, but they are always reviewed and documented afterward.
How the exam tests this
The CC exam tests this sub-domain with definition matching and order questions: naming the lifecycle stage an activity belongs to, putting the change management steps in sequence, and defining baseline, hardening, and configuration drift. Trigger words include no longer supported or no more patches (end of life: replace or isolate), deviation from approved settings (drift), standard configuration (baseline), and undocumented or unauthorized change causing an outage (change management failure). Expect a trap answer suggesting emergency changes skip documentation or review; they never do, they only defer them. Also expect the inventory principle stated as you cannot protect what you do not know you have.
Security Testing: Red, Blue, and Purple Teams, Scanning, SAST, and DAST
- Red team attacks, blue team defends, purple team is red and blue collaborating to improve both.
- Vulnerability scanning is automated, broad, and identifies known weaknesses; it does not exploit them.
- Penetration testing is authorized, manual, and deep: testers exploit vulnerabilities to demonstrate real impact.
- SAST examines source code without running it; DAST tests the running application from the outside.
- Threat modeling identifies threats during design; STRIDE is its recognition-level framework (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege).
- Physical penetration testing targets human and physical controls using phishing, tailgating, and impersonation.
- All legitimate security testing is authorized, scoped by rules of engagement, and documented; without authorization it is an attack.
How the exam tests this
The CC exam probes this sub-domain almost entirely through paired distinctions: red versus blue versus purple, SAST versus DAST, and scanning versus penetration testing. Trigger words include simulates attackers (red), detects and responds (blue), collaborate or share findings to improve (purple), source code without running it (SAST), running application (DAST), automated and known weaknesses (vulnerability scan), and exploit or demonstrate impact (penetration test). Expect distractors that blend definitions, such as a scan that exploits or a purple team described as a separate group. Threats identified during design, possibly naming STRIDE, means threat modeling; phishing, tailgating, or impersonation in a testing context means physical penetration testing.